<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Oct 28, 2015 at 10:42 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> and there are no errors in the logs.  It also tests successfully with TestShib.  This is the applicable attribute resolver and filter configurations.<br>
<br>
</span>You can't make this work without forcing the NameID format selection process to choose the "unspecified" format, and the only way to do that is via a relying party override and the nameIDFormatPrecedence property.<br></blockquote></div><br>While finishing my initial configuration of v3 last night, I decided to take a whirl with the recommendation in the documentation to try other than "unspecified" for Google (and Service-Now and Taleo).  Google doesn't seem to care which Format is sent, and I was able to successfully able to login with arbitrary Formats, as configured in my metadata for those providers.  (I thought I was going to have a fourth, but I just talked a vendor down from requiring "unspecified" or "persistent" - even though "persistent" clearly wasn't what they wanted.)</div><div class="gmail_extra"><br></div><div class="gmail_extra">Greg</div></div>